CVE-2007-4950 describes a disputed remote file inclusion vulnerability in PHPortal 0.2.7, specifically within the form/db_form/employee.php component. The vulnerability was initially reported to allow remote attackers to execute arbitrary PHP code by injecting a URL into the DOCUMENT_ROOT parameter. The CVSS score of 6.8 indicates a medium severity, with a network attack vector, medium attack complexity, and potential for partial compromise of confidentiality, integrity, and availability. However, CVE disputes this issue, stating that the DOCUMENT_ROOT parameter cannot be modified by an attacker, which would negate the exploitability. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. The vulnerability has garnered no community discussion or media coverage, suggesting a low level of attention and impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.2.7CPE matchmatch criteria | cpe:2.3:a:phportal:phportal:0.2.7:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.